Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Kiro) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

kiro-2-docker, kiro-2.21-docker, kiro-2.21.4-docker, kiro-docker

Index digest:

sha256:e3cd1336b61da88f127b2d0d679d7c0a5623ddfa83812614ac412159166b6882

Manifest digest:

sha256:ccf8ce4ff6980cc3e9e32b5e827289ce5a23d71e2b2ccb820da8b7e478a60c06

Size

1.01 GB

Last pushed

7 hours ago

Vulnerabilities

0
1
2
44
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:kiro-2-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:kiro-2-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:565743e0e436856f5444724ffc5da26b65154eefb7ec8c0a0ce9852ad8248668
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:a14488c6a6613e9bab215452604f60c8067f146936927a01919bdb7bb1896707
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:b677d70f5fea94d8fb9536556d9a3a806432f86f9ef7f672a0938774e9e54d9b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:5e25386d808a9eba07202d0742f6da51f546f7223420bd322bfdd9befabeec7e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:c70105e97168af4ca8084e0ce7f6892df675ef3b830da8ae85a8e6e005f25f71
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:b631c44c1ca4d56b514bcb08fb4795097319fea9c4aac53811c6b1f46171bd59
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:0488c5cf14a9ff03470b42bebc8321235160b76a0907588459f2b1f91a943508
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:38d86d6cd691309b3854d62ed90ff7534951d03453502962a34ddbc018af8927
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:2aa07b320ab6368bdd4ef858e7b0f23a428e0f31f37fad40fea765591a7eb6d6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:b8ca13c4ac1a5eee4b766904da733856b1fb4ee5e918a969d58172ed654c3d5e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:61bb0f7afc4b47b2a7cb90748f8f5f0c1b5b47beb30fe033183e3fb12baff773
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:a3a3534b675934f59760f75eb0667100b6408e1540879fcc59871bec3c8c308d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:2b87c8c8839abd16637855057c9819108f3045bd345c040633fe5600fe6cfdf9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:54392b6f2ca541689c770226d6a68faaeb0aed637a5f350522f1986d5db2c47d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:210a6cff29fc98e1d554b1eaf26df1d99876e0a4b7b906e9bb9e586c10da8c51